Arbitrary file upload in Trend Micro Mobile Security for Enterprise - CVE-2023-32526
Published: May 13, 2023 / Updated: May 14, 2023
Trend Micro Mobile Security for Enterprise
Trend Micro
Description
The vulnerability allows a remote user to compromise vulnerable system.
The vulnerability exists due to insufficient validation of file during file upload within the set_certificates_config action defined in the web/widgetforsecurity path. A remote user can upload a malicious file and execute it on the server.